Linuxsecurity Critical Privilege Escalation Flaws in Linux Kernel Affecting Multiple Systems
Article Content
- •CVE-2025-10263 and CVE-2025-54518 allow privilege escalation on affected systems.
- •Active exploitation of these vulnerabilities has been confirmed by CISA.
- •Administrators must update and reboot systems running affected Linux kernel versions.
On September 29, 2026, multiple vulnerabilities were disclosed in the Linux kernel, specifically affecting Ubuntu 24.04 and other distributions. These vulnerabilities include CVE-2025-10263, which allows local attackers to bypass memory protections on Arm processors, and CVE-2025-54518, which affects AMD Zen 2 processors, enabling privilege escalation. The flaws could allow attackers to write to memory after permissions were revoked, potentially compromising systems. Users of affected systems, including those running Oracle Cloud and AWS, are urged to apply the patches immediately. The vulnerabilities have been confirmed by CISA, which reported active exploitation of the Linux firewall flaw. The updates require a system reboot and may necessitate recompiling third-party kernel modules. Administrators are advised to check for the latest package versions to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Amazon Web Services and CVE-2025-10263 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Linux Kernel Vulnerabilities Affecting Ubuntu Systems Multiple critical vulnerabilities have been discovered in the Linux kernel affecting Ubuntu systems, particularly in versions 24.04 and 26.04 LTS. The vulnerabilities include CVE-2025-10263, which allows local attackers to bypass memory protections and escalate privileges on affected Arm and AMD processors. The issues…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…